The proper management of audit records and logs not only dictates proper archiving processes and procedures be established, it also requires allocating enough storage space to maintain audit logs online for a defined period of time.
If adequate online audit storage capacity is not maintained, intrusion monitoring, security investigations, and forensic analysis can be negatively affected.
It is important to keep a defined amount of logs online and readily available for investigative purposes. The logs may be stored on the AS or in some instances, Storage Area Networks (SAN) may be employed to meet this requirement. Regardless of method being used, audit record storage capacity must be sufficient to provide the defined number of days of continuous online operation. |